QTQuebecTaux
Banking

Fraudulent Interac E-Transfer: Prevention and Next Steps

Choose a security question that does not reveal the answer and verify the recipient’s details separately.

Published 2026-07-21

The historic Bank of Montreal head office in the evening

Transfer fraud forces no safe: it imitates a legitimate message at the right moment — new number, new payment address — and lets the victim do the transferring. Once accepted by the fraudster's recipient, a transfer is rarely recovered, which shifts the entire stake to prevention. Three rules constitute it. The security question, for sends that still require one: an unguessable answer, never contained in the question, delivered through a channel other than email. Change verification, the rule that blocks most fraud: any change in payment details gets confirmed through the old channel — a call to the number already known, never the one in the message announcing the change. Evidence last: send confirmations and deposit notices kept, time-stamped. If fraud strikes, immediate reporting — institution then authorities — remains the only factor that improves the odds. This article details the three rules and the hour-by-hour procedure after a transfer gone to the wrong place.

Choose a security question that cannot be guessed

An Interac e-Transfer protected by a security question rests entirely on that question's quality. The common ones — the dog's name, the city of birth, the rent amount — are often guessable from social media or from the transaction's context, and an intercepted email supplies the rest. A good question turns on a fact known only to the two parties and absent from all correspondence: a detail from a past conversation, something that appears neither in the listing nor in the written exchanges. The answer travels through a channel other than email, ideally spoken aloud.

Verify the recipient through an independent channel

Fraud at its costliest does not break the transfer: it changes the recipient. An email impersonating a notary, a contractor or a supplier announces a change of banking details and diverts a significant payment. The defence is constant: any change of details gets confirmed by phone, at a number known in advance rather than the one in the email, before sending. That verification takes two minutes and it is the only real protection, a transfer once deposited being in practice unrecoverable. The same principle applies to a first payment to any new payee.

Keep proof of the sending and the deposit

The deposit notice is the only confirmation that the money reached the right account, and it is kept like a receipt. The sending email, the deposit notice and the statement line together form the file that serves in a dispute with the payee. That file matters particularly for payments without an invoice, a deposit to a contractor or a purchase between individuals, where nothing else attests to the payment. Screenshots of the listing and the exchanges are kept alongside, an online listing often vanishing the moment the transaction closes.

Report fast, to the institution and the authorities

Hours, not days, make up the useful window after a fraud. The institution is contacted immediately: a transfer not yet deposited can sometimes be cancelled, a compromised account can be frozen, and prompt reporting conditions how the file is examined. A police report follows, with its file number, along with a report to the anti-fraud centre, which feeds investigations even without individual recovery. The file is assembled in parallel: chronology, original emails with their headers, transfer notices, file numbers obtained. The outcome stays uncertain, liability depending on the circumstances, but a late report almost always closes the door. Nothing about the process is fast, and none of it works retroactively.

Quebec scenario: compare before confirming

The message is a near-perfect imitation of her landlady's: new number, rent transfer to a new email address. A tenant in Farnham complies; the real rent, requested three days later, reveals the fraud. The transfer, auto-deposited through a hijacked address, is gone. Her immediate report, to the institution then the authorities, opens a file, but the outcome stays uncertain: a transfer accepted by the fraudster's intended recipient is rarely recovered. The experience rebuilds her entire transfer practice. The security question first, for sends that still require one: never a guessable answer, never the answer inside the question, and the answer delivered through a different channel than email. Verification next: any change in payment details gets confirmed by calling the number already known — never the number supplied in the message announcing the change, the rule that would have prevented everything. Evidence last: she now keeps the send confirmation and deposit notice of every transfer, time-stamped. Her landlady, informed, discovers her email had been compromised for weeks. Auto-deposit, the advisor notes, protects in one direction only: it removes the security question, not the need to verify the recipient — and the money travels at the speed of a click in both stories.

Checklist

  • Choose unguessable security questions
  • Send the answer through a separate channel
  • Verify any detail change through the old channel
  • Call the number already known, never the new one
  • Keep send confirmations and deposit notices
  • Enable auto-deposit knowing its limits
  • Report to the institution immediately in fraud
  • File with the authorities next
  • Document every step with dates

Frequently asked questions

How do I secure a transfer that uses a security question?

Three rules: an answer impossible to guess, never contained in the question, and delivered through a channel other than email — in person or by phone at the known number. Auto-deposit removes the question for recipients who enabled it, but not the need to verify the recipient.

What should I do about a change in payment details?

Verify through the old channel: call the number you already know, never the one supplied in the message announcing the change. That single rule blocks the majority of transfer fraud, all of which relies on an email compromised or imitated at the right moment.

Can a fraudulent transfer be recovered?

Rarely once deposited: report immediately to your institution and then the authorities, open a file and keep time-stamped send confirmations and deposit notices. Reporting speed is the only factor that improves the odds; prevention remains the real protection.

Sources

On the site

Read next